Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @snowscan
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @snowscan
-
Snowscan proslijedio/la je Tweet
RE just retired from
@hackthebox_eu. As the creator of the box, I tried to bring phishing/macro obfuscation concepts to the initial access. The intended privescs were the WinRar ACE file exploit, and XXE in Ghidra. I'll show two unintended privescs too.https://0xdf.gitlab.io/2020/02/01/htb-re.html …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Another box solved the unintended way: RE. Once I had RCE after dropping an aspx webshell with the Winrar CVE, I used the UsoSvc service to gain SYSTEM and impersonated the Coby user to decrypt the root flag. Great box by
@0xdf_. https://snowscan.io/htb-writeup-re/#HackTheBoxHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
I just published my writeup for the mini websockets challenge of the BottomlessAbyss BBS CTF: https://snowscan.io/bbsctf-evilconneck/ … Easy but fun challenge. Played with websockets in Python and did some HMAC secret bruteforcing.
@StackFault@pathetiqHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
I just made the switch from network architect/engineer to pentester this week. A bit of a career move risk but I feel it's gonna be worth it in the end. I needed to be challenged. Thanks to everyone who's helped me!
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
One more writeup for AI from
@hackthebox_eu is up: https://snowscan.io/htb-writeup-ai/ That SQL injection using text-to-speech gave me a hard time.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
I had a hard time finding the initial source code file for the launcher page on the Player box but I liked the LFI part using ffmpeg and the PHP deserialization priv esc at the end. https://snowscan.io/htb-writeup-player/ …
#HackTheBoxHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Snowscan proslijedio/la je TweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Snowscan proslijedio/la je Tweet
I was about to have a free weekend as
#CVE201919781 exploit work had been done by others already. Took the time to write about a more or less related project: Getting access to an encrypted appliance VM by modifying memory with help of VBoxDbg.https://github.com/ateamjkr/posts/blob/master/vboxdbg.md …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Snowscan proslijedio/la je Tweet
Citrix Netscaler AMIs on
@awscloud default vulnerable out of the box. The root password is set to the instance ID; that can be read from the metadata URL. CVE-2019-19781 from nobody to ssh as root in seconds.pic.twitter.com/an2jZ7qtcM
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
I didn't solve Bitlab the intended way but I still go over the initial shell with the PHP RCE. I used the git hooks method to gain root since git pull was sudo'ed root. Check out my writeup: https://snowscan.io/htb-writeup-bitlab/ …
#HackTheBoxHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Happy new year everyone. Craft just got retired today: a cool box with an eval vulnerability in the application REST API and vault installed to generate an OTP token to get root. Here's my writeup: https://snowscan.io/htb-writeup-craft/ …
#HackTheBoxHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Snowscan proslijedio/la je Tweet
lsassy 1.0.0 is finally out !
Remotely dump #lsass **with built-in Windows tools only**, procdump is no longer necessary
Remotely parse lsass dumps to extract credentials
Link to #Bloodhound to detect compromised users with path to Domain Admin https://github.com/Hackndo/lsassy pic.twitter.com/vljW7swZGr
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Snowscan proslijedio/la je Tweet
The
#CTF is going strong. A new challenge is opening in less than 2 hours! Don't forget to check out the door games tournament as well. See you in there! https://bbs.bottomlessabyss.net/connect#ansi#bbs#contest#tournamentHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Snowscan proslijedio/la je TweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Smasher2, one of the hardest box on HTB was just retired. Like many others, I did the auth bypass using an unintended bug in the web app. https://snowscan.io/htb-writeup-smasher2/ … If you want to check out the intended way , check out Overcast's blog post: https://www.justinoblak.com/2019/10/01/hack-the-box-smasher2.html …
#HackTheBoxHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Wall just got retired. I did this one by doing recon on github and finding the creator's repo. I went back after to find the intended way to bypass the HTTP basic auth. Here's my writeup: https://snowscan.io/htb-writeup-wall/ …
#HackTheBoxHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
I really liked the privesc for Heist where I took a memory dump of the running Firefox instance and grabbed credentials from it. I've posted my writeup for it here: https://snowscan.io/htb-writeup-heist/ …
#HackTheBoxHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Chainsaw's a pretty box cool. I learned about smart contracts while solving it. Check out my writeup: https://snowscan.io/htb-writeup-chainsaw/ …
@hackthebox_euHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Networked from
@hackthebox_eu was retired today. It's an easy box with an insecure upload vulnerability and command injections to escalate and gain root access.https://snowscan.io/htb-writeup-networked/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Jarvis from
@hackthebox_eu was retired today. Here is my writeup: https://snowscan.io/htb-writeup-jarvis/ … Easy box with SQL injection and command injection.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.